Patentable/Patents/US-10552834
US-10552834

Tokenization capable authentication framework

PublishedFebruary 4, 2020
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

Embodiments are directed to systems and methods for performing consumer authentication in a tokenized transaction. The token in the authentication request may be resolved to corresponding credentials before the consumer authentication process is initiated. As part of an authentication system, the merchant computer may include a merchant plug-in module as a proxy between the merchant computer and an issuer access control server. The merchant plug-in module may communicate with the issuer access control server by sending verification and authentication messages to the issuer access control server via a directory server. The token may be resolved to corresponding credentials before the authentication request reaches the issuer access computer for authentication. The merchant plug-in module, the directory server or a token router coupled to the issuer access control server may each be in communication with one or more token service providers to de-tokenize the token provided by the consumer's user device.

Patent Claims
18 claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

1. A method comprising: receiving, by a first server computer, transaction data associated with a tokenized transaction initiated by a user; determining, by the first server computer, that the transaction data includes a token, wherein the token comprises tokenized credentials; initiating, by the first server computer, a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying, by the first server computer, a token service provider among a plurality of token service providers; sending, by the first server computer, the token to the token service provider to detokenize the token comprising the tokenized credentials to form detokenized credentials; receiving, by the first server computer, from the token service provider, the detokenized credentials; forwarding, by the first server computer, the detokenized credentials to a second server computer for authentication; and receiving, by the first server computer, the detokenized credentials and an authentication value from the second server computer upon the second server computer authenticating the detokenized credentials before the transaction authorization process starts, wherein the authentication value and the token are incorporated into a transaction authorization request message after the transaction authorization process in connection with the tokenized transaction starts, and wherein the transaction authorization request message associated with the tokenized transaction includes at least the token and the authentication value.

2

2. The method of claim 1 , further comprising: sending, by the first server computer, the detokenized credentials to the token service provider after receiving the detokenized credentials and the authentication value to re-tokenize the detokenized credentials; and receiving, by the first server computer, the token associated with re-tokenized credentials from the token service provider.

3

3. The method of claim 2 , the method further comprising: sending, by the first server computer, the token and the authentication value to a third server computer for initiating the transaction authorization process using the token and the authentication value, wherein the first server computer is a directory server computer or a token router computer, wherein the third server computer is a merchant computer, and wherein the tokenized transaction is between the user and a merchant associated with the merchant computer.

4

4. The method of claim 1 , wherein the token in the transaction authorization request message is de-tokenized using the token service provider and sent to an authorization computer as part of the transaction authorization process.

5

5. The method of claim 1 , wherein the detokenized credentials include a unique primary account number.

6

6. The method of claim 1 , wherein the token service provider is identified among the plurality of token service providers based on a format of the token or based on one or more predetermined rules.

7

7. A server computer comprising: a processor and a computer readable medium coupled to the processor, the computer readable medium comprising instructions that, when executed by the processor, cause the processor to: receive transaction data associated with a tokenized transaction initiated by a user; determine that the transaction data includes a token, wherein the token comprises tokenized credentials; initiate a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying a token service provider among a plurality of token service providers; sending the token to the token service provider to detokenize the token comprising the tokenized credentials to form detokenized credentials; receiving from the token service provider the detokenized credentials; forwarding the detokenized credentials to a second server computer for authentication; and receiving the detokenized credentials and an authentication value from the second server computer upon the second server computer authenticating the detokenized credentials before the transaction authorization process starts, wherein the authentication value and the token are incorporated into a transaction authorization request message after the transaction authorization process in connection with the tokenized transaction starts, and wherein the transaction authorization request message associated with the tokenized transaction includes at least the token and the authentication value.

8

8. The server computer of claim 7 , wherein the computer readable medium further comprises instructions that, when executed by the processor, cause the processor to: send the detokenized credentials to the token service provider after receiving the detokenized credentials and the authentication value to re-tokenize the detokenized credentials; and receive the token associated with re-tokenized credentials from the token service provider.

9

9. The server computer of claim 8 , wherein the computer readable medium further comprises instructions that, when executed by the processor, cause the processor to: send the token and the authentication value to a third server computer for initiating the transaction authorization process using the token and the authentication value, wherein the server computer is a directory server computer or a token router computer, wherein the third server computer is a merchant computer, wherein the tokenized transaction is between the user and a merchant associated with the merchant computer.

10

10. The server computer of claim 7 , wherein the detokenized credentials include a unique primary account number.

11

11. The server computer of claim 7 , wherein the token service provider is identified among the plurality of token service providers based on a format of the token or based on one or more predetermined rules.

12

12. A system comprising: a first server computer including a first processor and a first computer readable medium coupled to the first processor, the first computer readable medium comprising instructions that, when executed by the first processor, cause the first processor to: receive transaction data associated with a tokenized transaction initiated by a user; determine that the transaction data includes a token, wherein the token comprises tokenized credentials; initiate a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying a token service provider among a plurality of token service providers; sending the token to the token service provider to detokenize the token comprising the tokenized credentials to form detokenized credentials; and receiving from the token service provider the detokenized credentials; and a second server computer including a second processor and a second computer readable medium coupled to the second processor, the second computer readable medium comprising instructions that, when executed by the second processor, cause the second processor to: receive the detokenized credentials directly or indirectly from the first server computer for authentication; authenticate the detokenized credentials; generate an authentication value upon authenticating the detokenized credentials; and send the detokenized credentials and the authentication value to the first server computer before the transaction authorization process starts, wherein the token and the authentication value are incorporated into a transaction authorization request message after the transaction authorization process in connection with the tokenized transaction starts, and wherein the transaction authorization request message associated with the tokenized transaction includes at least the token and the authentication value.

13

13. The system of claim 12 , wherein the first computer readable medium further comprises instructions that, when executed by the first processor, cause the first processor to: send the detokenized credentials to the token service provider after receiving the detokenized credentials and the authentication value to re-tokenize the detokenized credentials; receive the token associated with re-tokenized credentials from the token service provider; and send the token and the authentication value in the transaction authorization request message to a third server computer for initiating the transaction authorization process using the token and the authentication value, wherein the first server computer is a directory server computer or a token router computer, wherein the third server computer is a merchant computer, wherein the tokenized transaction is between the user and a merchant associated with the merchant computer.

14

14. The system of claim 12 , wherein the token service provider is identified among the plurality of token service providers based on a format of the token or based on one or more predetermined rules.

15

15. A method comprising: receiving, by a first server computer, transaction data associated with a tokenized transaction initiated by a user; determining, by the first server computer, that the transaction data includes a token wherein the token comprises tokenized credentials; initiating, by the first server computer, a user authentication process in connection with the tokenized transaction prior to a transaction authorization process in connection with the tokenized transaction, wherein the user authentication process includes: identifying, by the first server computer, a token service provider among a plurality of token service providers; sending, by the first server computer, the token to the token service provider to detokenize the tokenized credentials to form detokenized credentials; and receiving, by the first server computer, the detokenized credentials that were replaced with the token from the token service provider; receiving, by a second server computer, the detokenized credentials directly or indirectly from the first server computer for authentication; authenticating, by the second server computer, the detokenized credentials; generating, by the second server computer, an authentication value upon authenticating the detokenized credentials; and sending, by the second server computer, the detokenized credentials and the authentication value to the first server computer before the transaction authorization process starts, wherein the token and the authentication value are incorporated into a transaction authorization request message after the transaction authorization process in connection with the tokenized transaction starts, and wherein the transaction authorization request message associated with the tokenized transaction includes at least the token and the authentication value.

16

16. The method of claim 15 , further comprising: sending, by the first server computer, the detokenized credentials to the token service provider after receiving the detokenized credentials and the authentication value to re-tokenize the detokenized credentials; receiving, by the first server computer, the token associated with re-tokenized credentials from the token service provider; and sending, by the first server computer, the token and the authentication value in the transaction authorization request message to a third server computer for the transaction authorization process using the token and the authentication value, wherein the first server computer is a directory server computer or a token router computer, wherein the third server computer is a merchant computer, wherein the tokenized transaction is between the user and a merchant associated with the merchant computer.

17

17. The method of claim 16 , wherein the token in the transaction authorization request message is de-tokenized using the token service provider and sent to an authorization computer as part of the transaction authorization process.

18

18. The method of claim 15 , wherein the token service provider is identified among the plurality of token service providers based on a format of the token or based on one or more predetermined rules.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

April 30, 2015

Publication Date

February 4, 2020

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Tokenization capable authentication framework” (US-10552834). https://patentable.app/patents/US-10552834

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.